> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trylath.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Every Lath operation is POST https://platform.trylath.com/<operation name with dots replaced by slashes>, with a JSON body and `Authorization: Bearer <key>`. `email.send` is POST /email/send.
> Branch on `error.code`, never on `error.message`. Every refusal also carries `error.fix`, which names the next step.
> Send an `Idempotency-Key` header on any operation that is not retry-safe, so a retry cannot run it twice.
> A `lath_test_` key emails only the account's own members and sends no SMS; a `lath_live_` key reaches real recipients and is billed.
> The OpenAPI document, generated from the same registry as the routes, is at https://platform.trylath.com/openapi.json.

# developers.key.update

> Renames a key or changes the permissions it carries, in place. The key itself is untouched, so nothing has to be redeployed and no request fails while it happens. The new permissions take effect on the next request. A publishable key's one permission cannot be changed, permissions can only be set to what this caller itself holds, and the last key with developers:write cannot have it taken away.



## OpenAPI

````yaml /api-reference/openapi.json post /developers/key/update
openapi: 3.1.0
info:
  title: Lath API
  version: 0.1.0
  description: >-
    Every operation is one POST. The same set is reachable over MCP, the SDK and
    the CLI; nothing is dashboard-only.
servers:
  - url: https://platform.trylath.com
    description: This deployment
security: []
paths:
  /developers/key/update:
    post:
      tags:
        - developers
      summary: developers.key.update
      description: >-
        Renames a key or changes the permissions it carries, in place. The key
        itself is untouched, so nothing has to be redeployed and no request
        fails while it happens. The new permissions take effect on the next
        request. A publishable key's one permission cannot be changed,
        permissions can only be set to what this caller itself holds, and the
        last key with developers:write cannot have it taken away.
      operationId: developers.key.update
      parameters:
        - name: Idempotency-Key
          in: header
          required: false
          schema:
            type: string
          description: >-
            Replays the stored response for the same key and input; refuses
            different input.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                keyId:
                  type: string
                  format: uuid
                  pattern: >-
                    ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                name:
                  type: string
                  minLength: 1
                  maxLength: 60
                permissions:
                  description: >-
                    Replaces the key's permissions outright; not allowed on a
                    publishable key
                  minItems: 1
                  type: array
                  items:
                    type: string
                    enum:
                      - account:read
                      - account:write
                      - auth:read
                      - auth:write
                      - email:read
                      - email:write
                      - sms:read
                      - sms:write
                      - audience:read
                      - audience:write
                      - developers:read
                      - developers:write
                      - billing:read
                      - billing:write
              required:
                - keyId
              additionalProperties: false
      responses:
        '200':
          description: '{ activityId, result }. activityId is empty for reads.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  activityId:
                    type: string
                    description: The activity this call created, or empty for a read.
                  result:
                    $schema: https://json-schema.org/draft/2020-12/schema
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      name:
                        type: string
                      prefix:
                        type: string
                      permissions:
                        type: array
                        items:
                          type: string
                    required:
                      - id
                      - name
                      - prefix
                      - permissions
                    additionalProperties: {}
                required:
                  - activityId
                  - result
        '400':
          description: invalid_input or invalid_json
        '401':
          description: unauthenticated
        '403':
          description: forbidden
        '404':
          description: not_found
        '409':
          description: 'conflict: idempotency_mismatch, email_taken, last_key'
        '413':
          description: body_too_large
        '429':
          description: rate_limited
      security:
        - bearer: []
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: >-
        A Lath API key: lath_live_sk… or lath_test_sk… on a server,
        lath_live_pk… or lath_test_pk… in a browser.

````